SB2026040970 - Fedora 42 update for nix



SB2026040970 - Fedora 42 update for nix

Published: April 9, 2026

Security Bulletin ID SB2026040970
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) UNIX Symbolic Link (Symlink) Following (CVE-ID: CVE-2026-39860)

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to unix symbolic link following in fixed-output derivation output registration when copying temporary fixed-output derivation outputs from the build chroot. A remote attacker can create a symlink at the temporary output path to overwrite arbitrary writable files and escalate privileges.

This affects sandboxed Linux builds, while sandboxed macOS builds are unaffected.


Remediation

Install update from vendor's website.